SaaS
SaaS Release Notes - September 4, 2026
Release notes cover new features, enhancements, and fixes that have been released to production.
Identity Security Cloud is SailPoint’s next-generation identity security solution. It encompasses and builds on features and functions from IdentityNow. The release notes cover both Identity Security Cloud and IdentityNow features.
New features
| Product | What’s new |
|---|---|
SaaS Connectors - Spacelift SaaS | Identity Security Connectivity now supports the Spacelift SaaS connector. For more information, refer to Integrating SailPoint with Spacelift. |
SaaS Connectors - AWS SaaS | The AWS SaaS connector now supports agent discovery for Amazon Connect Customer, in addition to the existing Amazon Bedrock and Amazon Bedrock AgentCore agents. The connector aggregates Amazon Connect Customer instances, domains, AI agents, knowledge bases, prompts, guardrails, tools, and security profiles. For more information, refer to Integrating SailPoint and Amazon Web Services SaaS. |
SaaS Connectors - Bitbucket Cloud SaaS | The Bitbucket Cloud SaaS connector is now available in Identity Security Cloud. The connector supports:
This connector is read-only and does not support provisioning. |
SaaS Connectors - CircleCI SaaS | The CircleCI SaaS connector is now available in Identity Security Cloud. The connector extends visibility into non-human identities (NHIs) by aggregating checkout keys, SSH keys, and deploy keys. This connector is read-only and does not support provisioning. |
SaaS Connectors - Quick Compliance | Identity Security Cloud now supports the following connectors as Quick Compliance connectors: You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
Connectivity - N8N | The N8N connector is now available. The connector supports
For more information, refer to Integrating SailPoint with N8N. |
SaaS Connectors - Quick Compliance | Identity Security Cloud now supports the following connectors as Quick Compliance connectors: You can now expediently configure read-only connections to these sources for account and entitlement aggregation. For a full list of supported Quick Compliance sources, refer to Quick Compliance. |
Identity Security Cloud - SoD | FedRAMP customers licensed for Separation of Duties now have access to SoD Violation Management and SoD Violation Controls. For details, refer to Creating and Editing SoD Controls and Handling Policy Violations. |
Enhancements
| Product | Feature enhancements |
|---|---|
SaaS Connectors - Oracle HCM Cloud SaaS | The Oracle HCM Cloud SaaS connector now supports the following employee feeds:
|
SaaS Connectors - Microsoft Entra SaaS | The Microsoft Entra SaaS connector now batches all CSA updates into a single Microsoft Graph API request, eliminating sleep-based workarounds. This improves provisioning speed, reliability, and scalability. |
Connectivity - Microsoft Entra ID | The Microsoft Entra ID connector now uses the Azure Resource Graph API to aggregate both resource-attached and policy-assigned system-assigned managed identities (SAMIs) in a single request, ensuring complete managed identity coverage. |
SaaS Connectors - Salesforce SaaS | The Salesforce SaaS connector now supports provisioning the |
Connectivity - SalesForce | The Salesforce connector now persists Salesforce-rotated refresh tokens and renews access tokens automatically for sources configured with External Client Application authentication. This prevents reauthorization prompts following concurrent aggregation or provisioning operations. |
Connectivity - Oracle HCM Cloud | The Oracle HCM Cloud connector now supports the following employee feeds:
|
Identity Security Cloud - SoD | Separation of duties permissions can now be included in custom user levels. Refer to Custom User Level Matrices for details. |
Identity Security Cloud - Workflows | Workflows recommends adding trigger filters to all filterable trigger steps to prevent unintended high-executions causing workflow limits to be reached. |
SaaS Connectors - Application Visibility | Identity Security Cloud now lists browser extension discovered applications in a separate tab from SSO, CMDB, and PAM discovered applications. Additionally, unmanaged SaaS applications (Shadow IT) are now categorized by their security risk in the browser extension discovered applications tab. |
Fixes
| Product | Issue ID | Fixes |
|---|---|---|
Connectivity - SAP SuccessFactors | CONETN-5473 | The SailPoint SuccessFactors connector Fixed a timeout error in single account aggregation. The error occurred on sources with large Cost Center master data. It affected account schemas that included the |
SaaS Connectors - Microsoft Entra SaaS | CONHOWRAH-7529 | The Microsoft Entra SaaS connector schema no longer lists associated resources, as system-assigned managed identities do not support associated resources. |
Connectivity - ServiceNow | CONETN-5479 | The ServiceNow Identity Governance connector now applies the configured |
SaaS Connectors - Smartsheet | CONETN-5589 | The Smartsheet SaaS connector now retries configured retryable errors during provisioning operations. HTTP 429 is the default retryable error. |
SaaS Connectors - Slack SaaS | CONETN-5457 | Fixed an issue where the Slack SaaS connector omitted channels from the account after attribute synchronization or other provisioning updates. Channel entitlements could appear missing on the identity and Slack account until aggregation ran again. |
Non-Employee Risk Management | TRIAGE-16094 | Updated the Languages configuration page to use an edit link to change attribute name translations. |